Where every protection stands right now, in plain terms. Each item names what it does, and what changes for students once it is in place.
Keeping student documents supervised, and stopping documents from becoming private, unwatched spaces.
The youngest students cannot create documents or upload files, so they have no Drive of their own. They can still open and work in documents a teacher shares with them.
Students cannot share documents with each other, or receive shares from each other. This is enforced on Google's servers, so it holds on any device or browser — a phone, a home laptop, anywhere.
The moment a student is given edit access to a teacher-owned document, their ability to invite anyone else is removed — automatically, and within seconds.
Teacher-owned documents with two or more student editors that the teacher has not opened or edited for a set period automatically have those students dropped to view-only.
Delivering the SafeDoc setting changes the principals requested, and rolling out SafeDoc's own newly released updates, across all six student configurations.
Google Drive and Google Chat are reachable only from a managed school profile. From a guest window, a browser that isn't signed-in Chrome, or a browser signed in with a personal Gmail account, access is refused outright.
This is the protection that makes the others hold. It uses Google's Endpoint Verification, deployed to student devices, to recognize the managed profile; the block itself is server-side, and was tested and rolled out across the school.
A controlled way for a teacher to open collaboration for one assignment's documents only — for exactly the students who need it, for as long as they need it — instead of collaboration being all-or-nothing.
A full cleanout of every boys student's Drive — files moved into a per-student archive, and accumulated junk, stray uploads, shared-with-me items and shortcuts cleared out — including files that were held in the previous tenant.
Status: complete. A small number of shared-with-me or shortcut connections may linger after a thorough pass. (The Girls-division clearance was withdrawn at the school's request.)
Controlling who students may message, keeping conversations supervised, and giving leadership a graduated way to respond.
Chat is switched on only for the grades each division chose — Boys 5–8 and Girls 6–8 — and off for everyone below that.
The same server-side gate applied to Drive also covers Google Chat: it is reachable only from a managed school profile. From a guest window, a non-Chrome browser, or a browser signed in with a personal Gmail account, Chat is refused.
A student placed in this group can no longer start new messages, group messages, or spaces. Existing conversations continue, so it is a measured first step rather than a full shutoff.
Status: the restriction group is created in the Admin console and can be applied by hand today. The mechanism that moves students in and out automatically is part of the chat system, and is not yet built.
A student moved into this sub-group has chat fully disabled, while keeping every other policy of their grade unchanged.
Status: the sub-group with chat disabled is created. The mechanism that moves a student into it is not yet built.
For now, students are blocked from creating chat spaces at all. This holds the line until the capture-and-supervise system below is in place — at which point students can create spaces again and each one is automatically brought under supervision.
Delivered as a SafeDoc chat-configuration update across all configurations, per the principals' decisions.
When a student creates a chat space, it is automatically brought under supervision — converted to a monitored space, the student's ownership removed, and every member they try to add screened against the messaging rules.
Boys may message within their own grade; Girls within their own division. Enforced by controlling who is allowed into a conversation in the first place.
One-to-one and small-group messages between students who are not permitted to talk are detected and removed — including a group quietly spun out of a direct message.
Messages are screened by detection rules built specifically for this school. The rules are derived by analyzing last year's chats and the incidents that actually came up — turned into detection patterns tuned to catch bullying and inappropriate language as it really appears here, in English and in Hebrew or Yiddish. Tiered, so a severe match blocks and notifies, a milder one warns, and a watch list quietly logs.
Needs from the school: authorization to analyze last year's group conversations and incident history, so the detection is built from real data rather than guesswork.
Chat becomes reachable only during permitted hours, set per class and per timezone, so it is not open during lessons.
Needs from the school: bell times entered into the scheduling screens — per class, with each class's timezone. The rules are generated from that data directly.
A leadership view of flagged incidents — with the message, the surrounding context, and one-click ways to apply or reverse a consequence, all kept on the record.
An optional layer that reads the surrounding conversation to judge whether a flag is a genuine incident, and recommends a response — with a person always making the final call.